Firmware Vulnerability in Botslab G980H Dash Camera
CVE-2026-79959

7HIGH

Key Information:

Vendor

Botslab

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79959?

The Botslab G980H dash camera is affected by a vulnerability within its firmware that features a hard-coded root account password. This password is immutable by the user, creating a significant security concern. If an attacker gains access to the firmware or has physical possession of the device, they could retrieve the hard-coded credentials. This access allows unauthorized users to gain root-level control via the UART interface, potentially compromising device integrity and user privacy.

Affected Version(s)

G980H 30010_QHG980HN5294SysFW+

G980H 58_QHG980HMCN5291SysFW+

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Julian of Software Secured reported this vulnerability to CISA.
.